[Bug 26198] Re: Nautilus Thumbnail creation freeze system

2009-02-25 Thread Zeev Tarantov
The thumbnails contain original file modification timestamp. If file is 
changed, thumbnail is invalidated and recreated. If you're downloading a video 
using bittorrent it will be constantly changing until download is complete. 
Nautilus will make a thumbnail, then notice file has changed, make another 
thumbnail, etc.
Nautilus should see whether a file is opened for writing and not try to make a 
thumbnail for it.

-- 
Nautilus Thumbnail creation freeze system
https://bugs.launchpad.net/bugs/26198
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 338027] [NEW] libpng code injection CVE-2009-0040

2009-03-04 Thread Zeev Tarantov
*** This bug is a security vulnerability ***

Public security bug reported:

from http://www.libpng.org/pub/png/libpng.html:

Vulnerability Warning
All versions of libpng from 0.89c through 1.2.34 contain an uninitialized-data 
bug that can be triggered by a malicious user. Specifically, there are several 
instances in which a malloc'd array of pointers is then initialized by a 
secondary sequence of malloc() calls. If one of these calls fails, libpng's 
cleanup routine will attempt to free the entire array, including any 
uninitialized pointers, which could lead to execution of an attacker's code 
with the privileges of the libpng user (including remote compromise in the case 
of a libpng-based browser visiting a hostile web site). This vulnerability has 
been assigned ID CVE-2009-0040 and is fixed in version 1.2.35, released 18 
February 2009.

** Affects: libpng (Ubuntu)
 Importance: Undecided
 Status: New

** Visibility changed to: Public

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2009-0040

-- 
libpng code injection CVE-2009-0040
https://bugs.launchpad.net/bugs/338027
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 318445] Re: ffmpeg won't convert flv to mp3

2009-03-05 Thread Zeev Tarantov
In Jaunty, with version "3:0.svn20090204-2ubuntu1+unstripped2",
everything is ok with ffmpeg, but mplayer gives this error. I suppose
mplayer is linked with ffmpeg built-in rather than using the shared
library. My mplayer is 2:1.0~rc2-0ubuntu19.

-- 
ffmpeg won't convert flv to mp3
https://bugs.launchpad.net/bugs/318445
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 243453] Re: Please Upgrade Mplayer

2009-03-05 Thread Zeev Tarantov
Currently my mplayer gives the same error as described in this bug:
https://bugs.launchpad.net/ubuntu/+source/ffmpeg/+bug/318445

But since ffmpeg in jaunty is new, ffmpeg is actually fixed. But I still
can't play the file in mplayer, because it's old and isn't linked
against the new ffmpeg.

I realize linking against ffmpeg shared libs is problematic because they
break API/ABI compatibility often. But having to convert the H264/AAC
flv file to another container is quite ridiculous.

-- 
Please Upgrade Mplayer
https://bugs.launchpad.net/bugs/243453
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 336067] [NEW] python-httplib2 needs a patch for Python2.6 support

2009-02-28 Thread Zeev Tarantov
Public bug reported:

Binary package hint: python-httplib2

Upstream bug:
http://code.google.com/p/httplib2/issues/detail?id=39

Upstream commit:
http://code.google.com/p/httplib2/source/detail?r=275

Please include in Ubuntu Jaunty version until next upstream release.
This is important because Jaunty just upgraded the python package to
2.6.

** Affects: python-httplib2 (Ubuntu)
 Importance: Undecided
 Status: New

-- 
python-httplib2 needs a patch for Python2.6 support
https://bugs.launchpad.net/bugs/336067
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 322074] Re: oprofile-gui fails to start (missing libbfd)

2009-02-19 Thread Zeev Tarantov
I get:
w...@wolf-desktop:~$ opreport
opreport: error while loading shared libraries: libbfd-2.19.so: cannot open 
shared object file: No such file or directory

/usr/lib/libbfd-2.19.1.so exists, providing a symbolic link named
"libbfd-2.19.so" to it made opreport work.

oprofile 0.9.3-2ubuntu1
binutils 2.19.1-0ubuntu3

-- 
oprofile-gui fails to start (missing libbfd)
https://bugs.launchpad.net/bugs/322074
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 26198] Re: Nautilus Thumbnail creation freeze system

2009-02-25 Thread Zeev Tarantov
The thumbnails contain original file modification timestamp. If file is 
changed, thumbnail is invalidated and recreated. If you're downloading a video 
using bittorrent it will be constantly changing until download is complete. 
Nautilus will make a thumbnail, then notice file has changed, make another 
thumbnail, etc.
Nautilus should see whether a file is opened for writing and not try to make a 
thumbnail for it.

-- 
Nautilus Thumbnail creation freeze system
https://bugs.launchpad.net/bugs/26198
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 336067] [NEW] python-httplib2 needs a patch for Python2.6 support

2009-02-28 Thread Zeev Tarantov
Public bug reported:

Binary package hint: python-httplib2

Upstream bug:
http://code.google.com/p/httplib2/issues/detail?id=39

Upstream commit:
http://code.google.com/p/httplib2/source/detail?r=275

Please include in Ubuntu Jaunty version until next upstream release.
This is important because Jaunty just upgraded the python package to
2.6.

** Affects: python-httplib2 (Ubuntu)
 Importance: Undecided
 Status: New

-- 
python-httplib2 needs a patch for Python2.6 support
https://bugs.launchpad.net/bugs/336067
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 338027] [NEW] libpng code injection CVE-2009-0040

2009-03-04 Thread Zeev Tarantov
*** This bug is a security vulnerability ***

Public security bug reported:

from http://www.libpng.org/pub/png/libpng.html:

Vulnerability Warning
All versions of libpng from 0.89c through 1.2.34 contain an uninitialized-data 
bug that can be triggered by a malicious user. Specifically, there are several 
instances in which a malloc'd array of pointers is then initialized by a 
secondary sequence of malloc() calls. If one of these calls fails, libpng's 
cleanup routine will attempt to free the entire array, including any 
uninitialized pointers, which could lead to execution of an attacker's code 
with the privileges of the libpng user (including remote compromise in the case 
of a libpng-based browser visiting a hostile web site). This vulnerability has 
been assigned ID CVE-2009-0040 and is fixed in version 1.2.35, released 18 
February 2009.

** Affects: libpng (Ubuntu)
 Importance: Undecided
 Status: New

** Visibility changed to: Public

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2009-0040

-- 
libpng code injection CVE-2009-0040
https://bugs.launchpad.net/bugs/338027
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 318445] Re: ffmpeg won't convert flv to mp3

2009-03-05 Thread Zeev Tarantov
In Jaunty, with version "3:0.svn20090204-2ubuntu1+unstripped2",
everything is ok with ffmpeg, but mplayer gives this error. I suppose
mplayer is linked with ffmpeg built-in rather than using the shared
library. My mplayer is 2:1.0~rc2-0ubuntu19.

-- 
ffmpeg won't convert flv to mp3
https://bugs.launchpad.net/bugs/318445
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 243453] Re: Please Upgrade Mplayer

2009-03-05 Thread Zeev Tarantov
Currently my mplayer gives the same error as described in this bug:
https://bugs.launchpad.net/ubuntu/+source/ffmpeg/+bug/318445

But since ffmpeg in jaunty is new, ffmpeg is actually fixed. But I still
can't play the file in mplayer, because it's old and isn't linked
against the new ffmpeg.

I realize linking against ffmpeg shared libs is problematic because they
break API/ABI compatibility often. But having to convert the H264/AAC
flv file to another container is quite ridiculous.

-- 
Please Upgrade Mplayer
https://bugs.launchpad.net/bugs/243453
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 322074] Re: oprofile-gui fails to start (missing libbfd)

2009-02-19 Thread Zeev Tarantov
I get:
w...@wolf-desktop:~$ opreport
opreport: error while loading shared libraries: libbfd-2.19.so: cannot open 
shared object file: No such file or directory

/usr/lib/libbfd-2.19.1.so exists, providing a symbolic link named
"libbfd-2.19.so" to it made opreport work.

oprofile 0.9.3-2ubuntu1
binutils 2.19.1-0ubuntu3

-- 
oprofile-gui fails to start (missing libbfd)
https://bugs.launchpad.net/bugs/322074
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 338027] [NEW] libpng code injection CVE-2009-0040

2009-03-04 Thread Zeev Tarantov
*** This bug is a security vulnerability ***

Public security bug reported:

from http://www.libpng.org/pub/png/libpng.html:

Vulnerability Warning
All versions of libpng from 0.89c through 1.2.34 contain an uninitialized-data 
bug that can be triggered by a malicious user. Specifically, there are several 
instances in which a malloc'd array of pointers is then initialized by a 
secondary sequence of malloc() calls. If one of these calls fails, libpng's 
cleanup routine will attempt to free the entire array, including any 
uninitialized pointers, which could lead to execution of an attacker's code 
with the privileges of the libpng user (including remote compromise in the case 
of a libpng-based browser visiting a hostile web site). This vulnerability has 
been assigned ID CVE-2009-0040 and is fixed in version 1.2.35, released 18 
February 2009.

** Affects: libpng (Ubuntu)
 Importance: Undecided
 Status: New

** Visibility changed to: Public

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2009-0040

-- 
libpng code injection CVE-2009-0040
https://bugs.launchpad.net/bugs/338027
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 318445] Re: ffmpeg won't convert flv to mp3

2009-03-05 Thread Zeev Tarantov
In Jaunty, with version "3:0.svn20090204-2ubuntu1+unstripped2",
everything is ok with ffmpeg, but mplayer gives this error. I suppose
mplayer is linked with ffmpeg built-in rather than using the shared
library. My mplayer is 2:1.0~rc2-0ubuntu19.

-- 
ffmpeg won't convert flv to mp3
https://bugs.launchpad.net/bugs/318445
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 243453] Re: Please Upgrade Mplayer

2009-03-05 Thread Zeev Tarantov
Currently my mplayer gives the same error as described in this bug:
https://bugs.launchpad.net/ubuntu/+source/ffmpeg/+bug/318445

But since ffmpeg in jaunty is new, ffmpeg is actually fixed. But I still
can't play the file in mplayer, because it's old and isn't linked
against the new ffmpeg.

I realize linking against ffmpeg shared libs is problematic because they
break API/ABI compatibility often. But having to convert the H264/AAC
flv file to another container is quite ridiculous.

-- 
Please Upgrade Mplayer
https://bugs.launchpad.net/bugs/243453
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 26198] Re: Nautilus Thumbnail creation freeze system

2009-02-25 Thread Zeev Tarantov
The thumbnails contain original file modification timestamp. If file is 
changed, thumbnail is invalidated and recreated. If you're downloading a video 
using bittorrent it will be constantly changing until download is complete. 
Nautilus will make a thumbnail, then notice file has changed, make another 
thumbnail, etc.
Nautilus should see whether a file is opened for writing and not try to make a 
thumbnail for it.

-- 
Nautilus Thumbnail creation freeze system
https://bugs.launchpad.net/bugs/26198
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 336067] [NEW] python-httplib2 needs a patch for Python2.6 support

2009-02-28 Thread Zeev Tarantov
Public bug reported:

Binary package hint: python-httplib2

Upstream bug:
http://code.google.com/p/httplib2/issues/detail?id=39

Upstream commit:
http://code.google.com/p/httplib2/source/detail?r=275

Please include in Ubuntu Jaunty version until next upstream release.
This is important because Jaunty just upgraded the python package to
2.6.

** Affects: python-httplib2 (Ubuntu)
 Importance: Undecided
 Status: New

-- 
python-httplib2 needs a patch for Python2.6 support
https://bugs.launchpad.net/bugs/336067
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 322074] Re: oprofile-gui fails to start (missing libbfd)

2009-02-19 Thread Zeev Tarantov
I get:
w...@wolf-desktop:~$ opreport
opreport: error while loading shared libraries: libbfd-2.19.so: cannot open 
shared object file: No such file or directory

/usr/lib/libbfd-2.19.1.so exists, providing a symbolic link named
"libbfd-2.19.so" to it made opreport work.

oprofile 0.9.3-2ubuntu1
binutils 2.19.1-0ubuntu3

-- 
oprofile-gui fails to start (missing libbfd)
https://bugs.launchpad.net/bugs/322074
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 26198] Re: Nautilus Thumbnail creation freeze system

2009-02-25 Thread Zeev Tarantov
The thumbnails contain original file modification timestamp. If file is 
changed, thumbnail is invalidated and recreated. If you're downloading a video 
using bittorrent it will be constantly changing until download is complete. 
Nautilus will make a thumbnail, then notice file has changed, make another 
thumbnail, etc.
Nautilus should see whether a file is opened for writing and not try to make a 
thumbnail for it.

-- 
Nautilus Thumbnail creation freeze system
https://bugs.launchpad.net/bugs/26198
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 336067] [NEW] python-httplib2 needs a patch for Python2.6 support

2009-02-28 Thread Zeev Tarantov
Public bug reported:

Binary package hint: python-httplib2

Upstream bug:
http://code.google.com/p/httplib2/issues/detail?id=39

Upstream commit:
http://code.google.com/p/httplib2/source/detail?r=275

Please include in Ubuntu Jaunty version until next upstream release.
This is important because Jaunty just upgraded the python package to
2.6.

** Affects: python-httplib2 (Ubuntu)
 Importance: Undecided
 Status: New

-- 
python-httplib2 needs a patch for Python2.6 support
https://bugs.launchpad.net/bugs/336067
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 338027] [NEW] libpng code injection CVE-2009-0040

2009-03-04 Thread Zeev Tarantov
*** This bug is a security vulnerability ***

Public security bug reported:

from http://www.libpng.org/pub/png/libpng.html:

Vulnerability Warning
All versions of libpng from 0.89c through 1.2.34 contain an uninitialized-data 
bug that can be triggered by a malicious user. Specifically, there are several 
instances in which a malloc'd array of pointers is then initialized by a 
secondary sequence of malloc() calls. If one of these calls fails, libpng's 
cleanup routine will attempt to free the entire array, including any 
uninitialized pointers, which could lead to execution of an attacker's code 
with the privileges of the libpng user (including remote compromise in the case 
of a libpng-based browser visiting a hostile web site). This vulnerability has 
been assigned ID CVE-2009-0040 and is fixed in version 1.2.35, released 18 
February 2009.

** Affects: libpng (Ubuntu)
 Importance: Undecided
 Status: New

** Visibility changed to: Public

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2009-0040

-- 
libpng code injection CVE-2009-0040
https://bugs.launchpad.net/bugs/338027
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 318445] Re: ffmpeg won't convert flv to mp3

2009-03-05 Thread Zeev Tarantov
In Jaunty, with version "3:0.svn20090204-2ubuntu1+unstripped2",
everything is ok with ffmpeg, but mplayer gives this error. I suppose
mplayer is linked with ffmpeg built-in rather than using the shared
library. My mplayer is 2:1.0~rc2-0ubuntu19.

-- 
ffmpeg won't convert flv to mp3
https://bugs.launchpad.net/bugs/318445
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 243453] Re: Please Upgrade Mplayer

2009-03-05 Thread Zeev Tarantov
Currently my mplayer gives the same error as described in this bug:
https://bugs.launchpad.net/ubuntu/+source/ffmpeg/+bug/318445

But since ffmpeg in jaunty is new, ffmpeg is actually fixed. But I still
can't play the file in mplayer, because it's old and isn't linked
against the new ffmpeg.

I realize linking against ffmpeg shared libs is problematic because they
break API/ABI compatibility often. But having to convert the H264/AAC
flv file to another container is quite ridiculous.

-- 
Please Upgrade Mplayer
https://bugs.launchpad.net/bugs/243453
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 322074] Re: oprofile-gui fails to start (missing libbfd)

2009-02-19 Thread Zeev Tarantov
I get:
w...@wolf-desktop:~$ opreport
opreport: error while loading shared libraries: libbfd-2.19.so: cannot open 
shared object file: No such file or directory

/usr/lib/libbfd-2.19.1.so exists, providing a symbolic link named
"libbfd-2.19.so" to it made opreport work.

oprofile 0.9.3-2ubuntu1
binutils 2.19.1-0ubuntu3

-- 
oprofile-gui fails to start (missing libbfd)
https://bugs.launchpad.net/bugs/322074
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 26198] Re: Nautilus Thumbnail creation freeze system

2009-02-25 Thread Zeev Tarantov
The thumbnails contain original file modification timestamp. If file is 
changed, thumbnail is invalidated and recreated. If you're downloading a video 
using bittorrent it will be constantly changing until download is complete. 
Nautilus will make a thumbnail, then notice file has changed, make another 
thumbnail, etc.
Nautilus should see whether a file is opened for writing and not try to make a 
thumbnail for it.

-- 
Nautilus Thumbnail creation freeze system
https://bugs.launchpad.net/bugs/26198
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 336067] [NEW] python-httplib2 needs a patch for Python2.6 support

2009-02-28 Thread Zeev Tarantov
Public bug reported:

Binary package hint: python-httplib2

Upstream bug:
http://code.google.com/p/httplib2/issues/detail?id=39

Upstream commit:
http://code.google.com/p/httplib2/source/detail?r=275

Please include in Ubuntu Jaunty version until next upstream release.
This is important because Jaunty just upgraded the python package to
2.6.

** Affects: python-httplib2 (Ubuntu)
 Importance: Undecided
 Status: New

-- 
python-httplib2 needs a patch for Python2.6 support
https://bugs.launchpad.net/bugs/336067
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 338027] [NEW] libpng code injection CVE-2009-0040

2009-03-04 Thread Zeev Tarantov
*** This bug is a security vulnerability ***

Public security bug reported:

from http://www.libpng.org/pub/png/libpng.html:

Vulnerability Warning
All versions of libpng from 0.89c through 1.2.34 contain an uninitialized-data 
bug that can be triggered by a malicious user. Specifically, there are several 
instances in which a malloc'd array of pointers is then initialized by a 
secondary sequence of malloc() calls. If one of these calls fails, libpng's 
cleanup routine will attempt to free the entire array, including any 
uninitialized pointers, which could lead to execution of an attacker's code 
with the privileges of the libpng user (including remote compromise in the case 
of a libpng-based browser visiting a hostile web site). This vulnerability has 
been assigned ID CVE-2009-0040 and is fixed in version 1.2.35, released 18 
February 2009.

** Affects: libpng (Ubuntu)
 Importance: Undecided
 Status: New

** Visibility changed to: Public

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2009-0040

-- 
libpng code injection CVE-2009-0040
https://bugs.launchpad.net/bugs/338027
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 318445] Re: ffmpeg won't convert flv to mp3

2009-03-05 Thread Zeev Tarantov
In Jaunty, with version "3:0.svn20090204-2ubuntu1+unstripped2",
everything is ok with ffmpeg, but mplayer gives this error. I suppose
mplayer is linked with ffmpeg built-in rather than using the shared
library. My mplayer is 2:1.0~rc2-0ubuntu19.

-- 
ffmpeg won't convert flv to mp3
https://bugs.launchpad.net/bugs/318445
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 243453] Re: Please Upgrade Mplayer

2009-03-05 Thread Zeev Tarantov
Currently my mplayer gives the same error as described in this bug:
https://bugs.launchpad.net/ubuntu/+source/ffmpeg/+bug/318445

But since ffmpeg in jaunty is new, ffmpeg is actually fixed. But I still
can't play the file in mplayer, because it's old and isn't linked
against the new ffmpeg.

I realize linking against ffmpeg shared libs is problematic because they
break API/ABI compatibility often. But having to convert the H264/AAC
flv file to another container is quite ridiculous.

-- 
Please Upgrade Mplayer
https://bugs.launchpad.net/bugs/243453
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 322074] Re: oprofile-gui fails to start (missing libbfd)

2009-02-19 Thread Zeev Tarantov
I get:
w...@wolf-desktop:~$ opreport
opreport: error while loading shared libraries: libbfd-2.19.so: cannot open 
shared object file: No such file or directory

/usr/lib/libbfd-2.19.1.so exists, providing a symbolic link named
"libbfd-2.19.so" to it made opreport work.

oprofile 0.9.3-2ubuntu1
binutils 2.19.1-0ubuntu3

-- 
oprofile-gui fails to start (missing libbfd)
https://bugs.launchpad.net/bugs/322074
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 26198] Re: Nautilus Thumbnail creation freeze system

2009-02-25 Thread Zeev Tarantov
The thumbnails contain original file modification timestamp. If file is 
changed, thumbnail is invalidated and recreated. If you're downloading a video 
using bittorrent it will be constantly changing until download is complete. 
Nautilus will make a thumbnail, then notice file has changed, make another 
thumbnail, etc.
Nautilus should see whether a file is opened for writing and not try to make a 
thumbnail for it.

-- 
Nautilus Thumbnail creation freeze system
https://bugs.launchpad.net/bugs/26198
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 336067] [NEW] python-httplib2 needs a patch for Python2.6 support

2009-02-28 Thread Zeev Tarantov
Public bug reported:

Binary package hint: python-httplib2

Upstream bug:
http://code.google.com/p/httplib2/issues/detail?id=39

Upstream commit:
http://code.google.com/p/httplib2/source/detail?r=275

Please include in Ubuntu Jaunty version until next upstream release.
This is important because Jaunty just upgraded the python package to
2.6.

** Affects: python-httplib2 (Ubuntu)
 Importance: Undecided
 Status: New

-- 
python-httplib2 needs a patch for Python2.6 support
https://bugs.launchpad.net/bugs/336067
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 338027] [NEW] libpng code injection CVE-2009-0040

2009-03-04 Thread Zeev Tarantov
*** This bug is a security vulnerability ***

Public security bug reported:

from http://www.libpng.org/pub/png/libpng.html:

Vulnerability Warning
All versions of libpng from 0.89c through 1.2.34 contain an uninitialized-data 
bug that can be triggered by a malicious user. Specifically, there are several 
instances in which a malloc'd array of pointers is then initialized by a 
secondary sequence of malloc() calls. If one of these calls fails, libpng's 
cleanup routine will attempt to free the entire array, including any 
uninitialized pointers, which could lead to execution of an attacker's code 
with the privileges of the libpng user (including remote compromise in the case 
of a libpng-based browser visiting a hostile web site). This vulnerability has 
been assigned ID CVE-2009-0040 and is fixed in version 1.2.35, released 18 
February 2009.

** Affects: libpng (Ubuntu)
 Importance: Undecided
 Status: New

** Visibility changed to: Public

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2009-0040

-- 
libpng code injection CVE-2009-0040
https://bugs.launchpad.net/bugs/338027
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 318445] Re: ffmpeg won't convert flv to mp3

2009-03-05 Thread Zeev Tarantov
In Jaunty, with version "3:0.svn20090204-2ubuntu1+unstripped2",
everything is ok with ffmpeg, but mplayer gives this error. I suppose
mplayer is linked with ffmpeg built-in rather than using the shared
library. My mplayer is 2:1.0~rc2-0ubuntu19.

-- 
ffmpeg won't convert flv to mp3
https://bugs.launchpad.net/bugs/318445
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 243453] Re: Please Upgrade Mplayer

2009-03-05 Thread Zeev Tarantov
Currently my mplayer gives the same error as described in this bug:
https://bugs.launchpad.net/ubuntu/+source/ffmpeg/+bug/318445

But since ffmpeg in jaunty is new, ffmpeg is actually fixed. But I still
can't play the file in mplayer, because it's old and isn't linked
against the new ffmpeg.

I realize linking against ffmpeg shared libs is problematic because they
break API/ABI compatibility often. But having to convert the H264/AAC
flv file to another container is quite ridiculous.

-- 
Please Upgrade Mplayer
https://bugs.launchpad.net/bugs/243453
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 322074] Re: oprofile-gui fails to start (missing libbfd)

2009-02-19 Thread Zeev Tarantov
I get:
w...@wolf-desktop:~$ opreport
opreport: error while loading shared libraries: libbfd-2.19.so: cannot open 
shared object file: No such file or directory

/usr/lib/libbfd-2.19.1.so exists, providing a symbolic link named
"libbfd-2.19.so" to it made opreport work.

oprofile 0.9.3-2ubuntu1
binutils 2.19.1-0ubuntu3

-- 
oprofile-gui fails to start (missing libbfd)
https://bugs.launchpad.net/bugs/322074
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs